
Summary
Detects inbound messages containing a PDF attachment that matches specific YARA rules for embedded JavaScript or box lure patterns (pdf_js_function_box_lure, pdf_rect_size_box_lure). The rule targets inbound content, filters for PDF attachments, recursively explodes nested files/archives to expose inner content, and applies a YARA scan to identify the named lure signatures. It is labeled with medium severity and relates to credential phishing and malware/ransomware delivered via malicious documents. Detection relies on file analysis and YARA rule matching.
Categories
- Endpoint
Data Sources
- File
Created: 2026-08-20